RAKSHA

SEBI CSCRF — Cybersecurity & Cyber Resilience Advisor

← Hub SEBI CSCRF v1.0

Client Profile

Enhanced Obligations: MII and Qualified RE entities must comply with ALL mandatory CSCRF controls including dedicated SOC, Red Teaming, CART, ISO 27001 certification, CTI, and Digital Risk Protection Services.
WHY

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) 2023 mandates comprehensive cybersecurity for all market infrastructure institutions, stock brokers, depositories, and AMCs. Non-compliance risks penalties, trading restrictions, and loss of market participant registration. The framework requires SOC operations, regular audits, and incident response capabilities.

WHAT

SEBI CSCRF covers 6 domains — governance, identification, protection, detection, response, and recovery. Requirements include mandatory SOC (in-house or managed), vulnerability assessments, penetration testing, cyber audits, incident reporting to SEBI within 6 hours, and business continuity/disaster recovery testing.

HOW

We assess your current cybersecurity posture against SEBI CSCRF requirements, identify compliance gaps, and implement controls. We help set up or enhance SOC operations, establish incident reporting workflows, and prepare for SEBI cyber audits. Typical advisory: ₹8-40 lakh depending on market participant category.

Available OEM Vendors (9)

1

ServiceNow GRC

Governance, risk, and compliance management

2

Qualys

Cloud-based security and compliance scanning

3

Tenable

Vulnerability and risk management

4

Splunk

Security information and event management

5

CrowdStrike

Endpoint security and threat intelligence

6

MetricStream

Enterprise GRC and risk management platform

7

RSA Archer

Integrated risk and compliance platform

8

Rapid7

Vulnerability and incident detection

9

Scrut Automation

Risk and compliance management platform

Vendor-neutral. Customer-first. We recommend what you need — nothing more.

Compliance Dashboard
Overall Compliance Score 0%
0
Compliant
0
In Progress
0
Not Started
0
Non-Compliant
Critical Domains Loading...
High Priority Domains Loading...
Compliance Requirements — 11 Domains
Solution Mapping Matrix
SEBI CSCRF Compliance Requirement → Raksha Domain Advisor Mapping
SEBI CSCRF Compliance DomainEDREmailNGFWSIEMZTIAMDLPCloudDevSecBackupGRCNetMDR
A. Governance
B. Asset/Risk
C. SOC
D. Data Protection
E. Endpoint/App
F. VAPT/Red Team
G. Incident Resp
H. IAM
I. Third-Party
J. Backup/DR
K. Audit
Implementation Roadmap
1
Scoping & Assessment
Weeks 1–4
  • Determine RE category (MII/Qualified/Mid-Size/Small)
  • IT asset inventory and SBOM creation
  • Gap analysis against CSCRF requirements
  • Risk assessment for all critical systems
  • Identify mandatory vs recommended controls
2
Foundation Controls
Weeks 5–10
  • Cybersecurity governance framework setup
  • SOC establishment or MDR service engagement
  • IAM and MFA deployment
  • Network security architecture review
  • Incident response plan development
3
Core Implementation
Weeks 11–20
  • SIEM deployment and use case tuning
  • EDR/EPP rollout across all endpoints
  • DLP and encryption implementation
  • VAPT program with CERT-In auditor
  • Backup and DR infrastructure setup
4
Advanced Controls
Weeks 21–28
  • Red teaming and CART (MII/Qualified)
  • Digital risk protection deployment
  • TPRM program maturation
  • ISO 27001 certification (if applicable)
  • Security awareness training rollout
5
Continuous Compliance
Ongoing
  • Quarterly VAPT and remediation
  • Annual cybersecurity audit (CSCRF format)
  • Ongoing SOC monitoring and improvement
  • Regulatory filing and compliance reporting
  • Annual CCMP testing and policy updates
Penalty Reference — SEBI CSCRF
Non-compliance with CSCRF mandatory controlsSEBI enforcement action + Monetary penalty
Failure to establish SOC/monitoring capabilitiesBusiness restrictions + Penalty up to ₹1 Crore
Non-submission of cyber audit reportsWarning + Escalating penalties
Failure to report cybersecurity incidentsRegulatory action + Monetary penalty
Repeated non-compliance with CSCRFSuspension/cancellation of registration
Raksha Technologies
Cybersecurity Procurement Advisory · www.raksha.co.in